Sebastian Mallaby on OpenAI's Cash Crunch, the AI Bubble Debate, and the China AI Race

Sebastian Mallaby with Ed Elson

Show: Prof G Markets

Watch → · Listen →

Cleaned and reformatted from published transcript or auto-generated captions — punctuation added, filler removed, restructured for readability. Not verbatim. For exact quotes, refer to the original.

Contents

    OpenAI's runway and the IPO delay

    Ed Elson

    Cracks are forming in the OpenAI story. Last week, the company reportedly proposed giving the US government a 5% stake worth roughly $43 billion, as a way to share the upside of AI with the public. Critics argue it would amount to a government bailout, and see it as a troubling signal for both OpenAI and the broader AI boom.

    That news came after reports that OpenAI had pushed back its IPO plans until 2027, adding to concerns about the company's financial position. So we wanted to speak with someone who has spent years studying the history of AI, and who also believes that OpenAI could run out of money in the near future. Sebastian Mallaby is a prominent journalist, author, Pulitzer Prize finalist, and senior fellow at the Council on Foreign Relations. Today he's joining us to discuss what's next for OpenAI, what's next for the AI industry, and what investors should be watching.

    Sebastian, thank you so much for joining me. I'd love to start with an article you wrote back in January, titled "This is what convinced me OpenAI will run out of money." You said then, quote, "My bet is that over the next 18 months, OpenAI runs out of money." We've seen a lot of red flags since — the delayed IPO, and this proposal for the US government to take a stake in the company. What do you make of the recent news, and do you hold to your prediction?

    Sebastian Mallaby

    Yeah, I do hold to my prediction. Back in January the burn rate was just crazy. Although OpenAI had good products and quite a lot of traction — 900 million consumers — they won't be able to charge money for most of that. Only about 5% of retail consumers were actually paying. If you look at a chart of where these users are, the US is the number two market, India is first, and the next three are Brazil, Indonesia and so on. These are not rich consumers — you can't charge them very much money.

    So they had a business model that imagined they could throw money in all directions: a collaboration with Jony Ive to build a new form factor that would supplant the iPhone, Sora video-generation models, and so on — all very expensive. And the revenue side simply wasn't there. The burn seemed to me totally unsustainable. Even though Sam Altman is a magician when it comes to raising money, he wasn't going to raise the $660 billion that internal documents projected as the burn rate for the next five years.

    Since then, there has been some good news. OpenAI recognised it had to get the burn rate down. It's pulled out of a bunch of data-centre building projects — Stargate and so on. It's cancelled Sora, the video model, which was a total money loser, and it's tried to impose some order on the chaotic management, though only half successfully. In the meantime, OpenAI is squeezed between Anthropic, which is much better at frontier enterprise applications like coding assistants, cybersecurity and agentic work, and Gemini from Google DeepMind, which has reached more retail consumers and monetises far better because Google has plugged AI into its search-advertising business, which is now doing more revenue than ever.

    I think OpenAI is technically a good lab, but it's very hard to monetise when your product has a lot of competition, is kind of a commodity, and you're not terribly well managed. They've relied too much on the fake-it-till-you-make-it Silicon Valley tactic — smoke-and-mirrors fundraising. Look at the fundraising they announced earlier this year: the headline number was $122 billion, an astronomical figure. But when you dig in — and I'm amazed the press didn't point this out more — about two-thirds of that was promises conditional on a successful IPO, or payment in kind like compute access. The real money was a small share of the total. Why announce a $122 billion headline number when anyone who digs in can see it's rubbish? Because they're trying to head-fake investors into putting more money in, to persuade people they have momentum. They don't. The IPO delay is just the latest evidence that they took a big gamble but are behind where they say they are.

    Ed Elson

    Do you think the IPO delay was in large part because of all this — because Sam Altman and the company know that as soon as Wall Street gets an audited look at their financial statements, the tide will turn, and people will say "sure, you have a great product, but this is not a sustainable business model"? Do you think that was the concern — that people might actually see how the company works?

    Sebastian Mallaby

    100%. Everybody remembers the WeWork story — WeWork was this rocket ship back in 2019, it went out with a prospectus for its IPO, and people looked at it and said this is a joke, nobody wanted to buy the shares, and the IPO never happened. So you can fail by going for the IPO. OpenAI is in a very tough position: on the one hand it needs the IPO, because it can't raise enough money staying private; on the other, if it tries the IPO it may not succeed, and then it's really cooked.

    Anthropic vs OpenAI

    Ed Elson

    Just looking at how much they're spending — we saw the financials released by Ed Zitron, the independent journalist who got hold of the numbers. They generated $13 billion in revenue last year, spent $34 billion, meaning an operating loss of $21 billion — the net loss was even higher, but that's a good rough estimate of how the business is doing.

    You mentioned they're stuck between Gemini and Anthropic. Anthropic is interesting because we also don't know much about that business — we know they're unprofitable, we know they're in a similar business to OpenAI, and this technology is becoming increasingly commoditised. There were reports they were coming up on a quarter of operating profitability, but I think we have to take that with a grain of salt, since we don't know their accounting. My question: how does Anthropic compare to OpenAI from a business-model perspective?

    Sebastian Mallaby

    That's a good point, and I agree we don't know as much as we would if Anthropic were a public company with a public prospectus. What we do know is that Anthropic has always targeted enterprise customers — the type that actually pay for the product — and that it's been ahead on things like coding assistants and cybersecurity AI. Not that OpenAI is bad — it's not far behind — but I think Anthropic is the cutting edge on the applications enterprises are really willing to pay for.

    Anthropic also hasn't been distracted into announcing a whole suite of retail-oriented initiatives that came to nothing. OpenAI announced it was going to do shopping, and that doesn't seem to have happened. It said it was going to do ads — not sure they've got terribly far. It generated Sora, which was a huge money loser. Anthropic never went down that path. So Anthropic has been way more laser-focused on the part of the market that makes sense — enterprise — and just better managed.

    The other point is that Anthropic, among the frontier labs, is known for the lowest scientist churn. People go there, they believe in the mission, they believe in Dario Amodei as leader, and they tend to stay. They don't job-hop, whereas the other labs are subject to constant job-hopping, which is obviously disruptive.

    An OpenAI bubble, not an AI bubble

    Ed Elson

    One of the questions in investors' minds, especially if you're worried about an AI bubble popping, is: is this an OpenAI problem or an AI problem? Is OpenAI just bad at managing its finances, pursuing side projects it can't control the spending on? Or is AI as a business model just too expensive relative to the revenue you can generate by charging customers for ChatGPT, or charging enterprises for AI contracts? What's your view? For context — you wrote The Power Law, one of the most famous books on venture capital, about how venture works as a model where you lose money for years before eventually figuring it out. Is AI going to be that story, or is this different?

    Sebastian Mallaby

    My view is that we have an OpenAI bubble but not a general AI bubble. For the reasons we've discussed, I think OpenAI is 50/50. It might work — I'm not saying I know they'll fail. I'm saying there's a 50% chance that by next summer we'll find they couldn't go public, couldn't raise enough in the private markets, and have to sell themselves at a discount to another company — Amazon, Microsoft, or someone else that wants an AI team, because technically OpenAI is a good team.

    On the broader question: there's debate about whether enterprise customers are having an "oh my god" moment, realising these tokens are expensive. I've spent the last 18 months telling my own teams to go wild with AI, experiment, token max — the more tokens you use, the more you're showing you're AI-forward. Now it's, wow, this is expensive and I haven't seen a productivity gain yet, so what am I doing? There are lots of stories about companies imposing a middle layer between the user and the models, routing a simple query to a cheap, low-token model, and only a genuinely hard one to something expensive. So there's some sensible rationalisation happening about how customers spend on this technology.

    But fundamentally, if you look at what's happened since ChatGPT's release, the clear story is unbelievably fast progress. When ChatGPT came out, it hallucinated non-stop. GPT-4 arrived six months later and cut about 80% of the hallucination. Then very long context windows, so you could put a whole Tolstoy novel into the model and query it. Then reasoning systems that could do maths and logic, which had been impossible before. Then agentic systems, coding assistants, cybersecurity systems. Now you've got bespoke AI autonomous scientists emerging. That is unbelievably fast progress. So I fundamentally think AI as a sector — and therefore the demand for semiconductors, data centres, all the things people worry about — isn't a bubble. It's for real. It's going to take some time for companies to figure out how to ration their people's token use sensibly, but they're going to keep consuming a lot of tokens.

    Meta's cloud pivot — bear or bull signal

    Ed Elson

    Another data point the bears might raise, from last week: Meta launching its cloud business. This is the argument against what you're saying — which, by the way, I agree with, but let me play devil's advocate. The very thing Meta said it wouldn't do, it's now doing. It said it would only launch a cloud business if it had, quote, "overbuilt" — Mark Zuckerberg's words a few months ago. The plan was: build out all this data-centre capacity because we need it desperately for our internal AI products, we're going to AI-turbocharge our business. Then they turn around and say, actually, we don't have the internal demand we thought we did, so we're going to sell the capacity to someone else and let someone else figure out how to make an AI product profitable. That seems quite bearish from a bubble perspective — if Meta can't crack it, if OpenAI is struggling to crack it, and it's TBD on Anthropic, then who's going to crack this? Who's going to make it not just interesting technology, but interesting technology that makes money?

    We've seen the same with SpaceX — they've also decided to sell compute capacity to Anthropic and others, because their own model, xAI, hasn't got much uptake, so they don't need all the compute they've built for it. So you could read this as a bear signal, as you've described, or as a bull signal — it means some consolidation is happening in the frontier model space, and less competition means better margins, maybe more pricing power, for whoever's left standing.

    Sebastian Mallaby

    I don't agree that's the proper reading. The proper reading is that we're seeing a rationalisation of the market. Three or four months ago, across the whole US ecosystem, you had xAI trying to compete, Meta trying to compete, plus the big three — Google DeepMind, OpenAI and Anthropic. That's five, before you count Mistral in France, Cohere in Canada, and all the Chinese models. That's a lot of competition, and I don't think it consolidates down to a winner-takes-all, 2010s-social-media-platform outcome. But some consolidation is in order, so it ends up looking like cloud computing, with three or four big providers. Now we've got three leaders standing in the US, plus the foreign ones. That feels good to me for the sector's future business stability.

    Ed Elson

    If OpenAI runs out of money, as you predict, what do you think the outcome would be? You've written that maybe it would be absorbed by another company. How does that play out if what you're saying happens?

    Sebastian Mallaby

    We've seen plenty of examples of acquisitions, or more recently acqui-hires — a smallish AI company like Inflection, which Mustafa Suleyman was running, got sucked into Microsoft; Character.AI got sucked back into Google. There's a playbook here. OpenAI is a lot bigger than either of those, so it would be a more complex playbook, but the demand for AI talent and AI products, and the compute infrastructure underneath it, isn't going away — this is useful stuff people are going to figure out how to use productively.

    So I don't know whether the whole of OpenAI gets bought by Amazon, Microsoft or some other acquirer, or there's some fancy acqui-hire where part of OpenAI gets sucked into a big company, or there's a splintering where the technical staff get individually hired into other labs. Who knows. What I'm saying is there's a fundamental problem with the way they're running their business model. I think they understand that — it's why they've pulled out of data-centre building and other things over the last six months — but they've got some way to go to fix and patch things up.

    One of the lessons from how startups work, from my previous book The Power Law, is that when you have a very high valuation, a down round is super painful. They were valued in the last round at around $850 billion post-money, and in the secondary market they're trading for a lot less than that. If they were to just say, okay, we accept we're really worth $600 billion, the hit to everybody's equity options inside OpenAI would be horrible, and they would lose people. The hit to investors who'd believed in OpenAI would be bad, and they'd get pissed off, and the whole momentum machine that Altman has built would go through a convulsion. It might be what you have to do to make the thing sustainable, but my point is: once you ratchet all the way up to a very high valuation, it's difficult to climb down.

    The government stake and 'cheating capitalism'

    Ed Elson

    That, I think, is why he's proposing giving the government 5%. A strategy to get out of the box he's in is for Altman to give a stake to the government, and then the government says OpenAI is too important to fail, because we own 5% or 10% of it — and they do what they did with Intel, where they took a 10% stake last year, and next thing you know Commerce Secretary Lutnick is calling other tech companies in the Valley, telling them they're going to do a deal with Intel, bring Intel in as a partner on their next project. You've got the US government, a Trumpy US government, strong-arming other companies into giving business once it's in your corner. That, I think, is Sam Altman's strategy — recruit the investment banker to whom you can't say no, the US government — which is basically trying to take a workaround shortcut around capitalism.

    It seems like we're increasingly seeing that if you can't figure it out in the free market, you go to Washington, walk into the White House, and hope he'll save you. We're seeing the government take up stakes in multiple companies, and the odds it will take stakes in even more are rising — they may well take a stake in OpenAI. Last I checked the prediction markets, the odds of that were more than a third. It's possible they'd do the same with Anthropic, with Palantir, with Anduril. It makes me very upset, because I think of it as cheating — cheating the game of capitalism. I'd be curious to get your view. And following up: if that happens — say OpenAI is running out of money and Trump bails them out with taxpayer dollars — what comes after that? Does that mean OpenAI is fine? Does it mean the rest of the AI industry is on shaky ground? I'm not quite sure how to even model that scenario.

    Sebastian Mallaby

    First of all, I think your formulation — that they're cheating capitalism, doing an end-run around it — is a good, perceptive, and quite amusing insight, so thank you for that. I'd also say this is just the way the world is going, or at least the US. If you look at the number of American companies in which the US government has announced or consummated a deal — a colleague of mine, Jonathan Hillman at the Council on Foreign Relations, did a formal count, which just went up on the Council's website — the answer is 30 such companies since the Trump team came into power in January 2025, where the US government holds an equity stake in a private company.

    So this is where the world is going, and the trend has been very much encouraged by the deceptive example of Intel. Look at Intel's performance since the government took a stake last August — it's been fantastic, way better than the Philadelphia Semiconductor Index, the normal comparable. Intel is up almost 400%; the index is up about 150%. Intel has done incredibly well since the government came in, and people lose sight of the fact that it did well because the Commerce Department is calling other companies and ordering them to do business with Intel. Intel gets a bunch of contracts and turns its game around because the government is picking a winner.

    Now, it's one thing to say the government might have a justification for picking a winner when we have a problem with cutting-edge semiconductors all being made in Taiwan — we don't want to be reliant on an island that could be invaded by China, so we want domestic semiconductor manufacturing. I get that argument. I don't believe in extending it to OpenAI, which is just one of multiple American foundation-model builders. We don't need OpenAI for any strategic reason, so there's no justification for picking a winner around it. Capitalism is sometimes justifiably twisted because of a national-security reason. Backing OpenAI would not be a justifiable instance.

    Ed Elson

    I could imagine the justification floated is that OpenAI isn't systemic to the real economy, but they'd argue it's systemic to the stock market — because Microsoft's future revenues depend so heavily on OpenAI, and Google, Amazon, xAI, basically all the hyperscalers, Oracle — a lot of these companies are hugely important to portfolios. They're what make wealthy people wealthy. Maybe the argument would be: we need to keep this thing afloat, otherwise people's stocks go down. What would you make of that argument?

    Sebastian Mallaby

    I'd say welcome to China. That's the kind of thing the Chinese government would do — prop up the stock market with intervention of that sort. In the United States, when the Federal Reserve operates a policy that even looks like it's about stabilising the stock market, people freak out and call it a Fed put, and say it creates more bubbles down the line — capitalism doesn't work unless there's real risk involved. If you have a bunch of political types in Washington — the Commerce Department and so on — picking winners and distorting market outcomes, you don't have a market anymore. It's not free. To put your point differently: this is an end-run against the idea of a fair, level playing field on which companies compete and the most efficient ones win. That's supposed to be the wellspring of efficiency in American capitalism. If you start tilting the playing field by picking OpenAI as a winner, you've just trashed that.

    China's AI progress

    Ed Elson

    We're back with Prof G Markets. This is a good segue into China, a topic you also wrote about recently — your piece in the New York Times was titled, quote, "I went to China to see its progress on AI. We can't beat it." What did you learn about Chinese progress on AI, and why do you think we can't beat it?

    Sebastian Mallaby

    We haven't mentioned this yet, but I'm going to mention it now, since you've given me the excuse — I published a book this year called The Infinity Machine, about Demis Hassabis and—

    Ed Elson

    I was going to get to it.

    Sebastian Mallaby

    —DeepMind. There you are.

    Ed Elson

    I'm glad you mentioned it.

    Sebastian Mallaby

    Go read The Infinity Machine, folks. But no, seriously — the thing about China is it does everything faster. They got my manuscript last, then had to translate it into Chinese, then wanted photographs and other embellishments, so they produced a more complex product, but they actually published it before Penguin Press in the United States, or any of my other deals elsewhere.

    So I go to China right at the start of my book tour. I spent eight days across four cities — Hangzhou, Shenzhen, Shanghai, Beijing — talking to computer scientists at private labs like Huawei and Ant Group, and to academic computer scientists at universities. What struck me first is that they talk about safety — they bring it up unprompted. The notion I've heard from friends in Washington, that the Chinese don't give a damn about AI safety, is just not true. They do talk about it. I'm not claiming government policy is to pursue safety, or that the majority view in China wants safety — China is like the US, it has accelerationists and people who want to go slower because they're worried about safety. Neither side is going to de-escalate unless the other does too. But it's wrong to caricature China as 100% acceleration. There is scope to talk to them about safety.

    The other thing I observed is that China is very good, and very focused, on applications. Go to a company like Hikvision, which is under US sanctions, and it's an out-of-body, double-take experience — on one hand it feels like an American tech company. I love tech companies, all about building cool things and making the world better — I drink that Kool-Aid, I believe in it. I see these people building cool technology. They showed me an AI scanning camera you point at water to get a reading on pollution levels — and because they can measure it, there's now an internal market in water-pollution reduction between different Chinese cities. The downstream city pays the upstream city to reduce the pollution flowing down to it. You can only do pollution reduction once you can measure the pollution, and that's what this company is building.

    But they're also under sanctions, because the US says — and historically this was true — that they build other kinds of cameras good for surveillance of civilians in Xinjiang and elsewhere. So they're both bad guys and cool guys — a difficult thing to reconcile. But whatever they are, they aren't going away. These are real companies building real technology. Go to Huawei and they've got application after application — a special AI to service the bullet train between Shanghai and Beijing every evening. We used to have human mechanics go under the train to check it; now they just have AI cameras and a couple of robots that fix it. They're doing this. We're not stopping them. We've imposed chip export controls on China to hold them back, and it hasn't worked — they're moving ahead.

    The latest thing is a model from a group called JIPU in China, which isn't quite as good as mythos from Anthropic, but it's pretty close. We're kidding ourselves if we assume away the reality of China as a technology superpower. We need to get our heads out of the sand and start talking to China about what happens when they have a mythos-level model that could hack every single bank in the global financial system and wreak havoc. We need to persuade them not to release it on an open-source, open-weight basis, because then any criminal can use it, and there won't be an off switch.

    Ed Elson

    What's your view on AI policy toward China? The big debate is whether we should have export controls — should we sell chips to China, are we selling weapons to our enemy, do we need to sell dumber chips, or should there be no export controls at all? Do you think we need a policy, or is the path forward more a matter of diplomacy?

    Sebastian Mallaby

    I believe in American power, first of all. I work at the Council on Foreign Relations in New York, we do geopolitics all day long, and I believe US power is generally a force for good. So I'd rather the Chinese were behind on AI. To the extent a chip export ban helps us stay ahead, I support it — when it was first announced in 2022, I wrote a long essay in the Washington Post about why it was a good idea. But my doubts recently come from looking at the results: I'm not seeing Chinese models that far behind. And because they're not far behind, we have to reckon with the reality that they're building models that will destabilise the global cyber system. Unless we persuade them not to release these on an open-weight basis, which is what they're doing now, we have serious trouble on our hands — everything in cyberspace gets destabilised, and we need a policy to deal with that proliferation risk. I'm in favour of the chip export ban if we could have it for free, with no downside. But if the effect of chip export controls is that we can't talk to them about an agreement on not releasing open-weight mythos-level models, I'm willing to trade a bit on the export ban.

    Distillation and chip export controls

    Ed Elson

    Looking at how these models have affected the ecosystem — in the US you've got Anthropic, OpenAI and Gemini as the heavyweights right now. But as pricing becomes more of an issue, companies are more interested in cheaper models, which usually means Chinese models. That's exactly what we're seeing on OpenRouter, which tracks developer traffic across AI models — Chinese models went from less than a third of developer traffic in late 2025 to 60% by mid-2026. American companies have started using Chinese models — Cursor, Airbnb, Shopify, Uber; Microsoft is currently testing DeepSeek. What do you make of this shift to Chinese models, and what role does it play in the policy discussion?

    Sebastian Mallaby

    It shows they're making good models that serious American companies are considering using. That's another argument for why you can't just pretend China can be beaten and leave it there — these guys are for real, and we have to work with them, not just against them.

    It's useful to think through the lens of the Cold War. With nuclear weapons, there were two kinds of big risk: one was a nuclear conflagration between the Soviet Union and the United States, which we prevented through mutually assured destruction — close parity in the two arsenals, and therefore deterrence. The other was proliferation of these weapons to rogue states or terrorists, which we dealt with through a separate mechanism, the non-proliferation regime. We were competing fiercely with Russia — an arms race, the Cuban Missile Crisis, being told at the UN "we will bury you," as Khrushchev said while banging his shoe on the table. So there was deadly serious competition between the two superpowers, but also cooperation on non-proliferation. I see the AI future the same way — inevitable competition between China and the US, but also, I hope, collaboration, because the proliferation risk is too awful to contemplate without it.

    Ed Elson

    It seems what they're doing is basically stealing what we have — people are calling it distillation. You wrote about this; your definition was, quote, "Every time a US lab produces a cutting-edge model, Chinese rivals quickly reverse-engineer its capabilities and build a copycat version — the follower has the advantage." When companies switch to Chinese models because they're cheaper, using the expensive American frontier models only for certain tasks and Chinese models for others, it seems like we're seeding advantage to the Chinese players. And it seems the reason those models are good and cheap is distillation — i.e. theft. I don't know if I'm being crude calling it theft.

    Sebastian Mallaby

    I don't think you are. I think the Chinese have shown a pretty strong track record of stealing intellectual property from the US and then monetising it on their own terms.

    Distillation is a process where, once a strong new American model comes out, a Chinese copycat asks it a ton of questions and harvests the answers as training data — if the question is like this, the answer should be like that. When a first-mover American lab has to train a model in some complicated frontier expertise — say quantum physics — it expensively hires a bunch of quantum physicists to create problem sets, model questions and answers, generating that training data. That's a super expensive, time-consuming, painful process. But once you've built an AI that can replicate all those quantum physicists, the Chinese can come along, skip hiring the human physicists, and just query the machine equivalent. That's distillation.

    When Chinese companies do this, it isn't illegal, but it is against contract — when you sign up to use an American model, you agree not to query it endlessly and train your own model by copying its outputs. So they're violating contract, not federal law, as I understand it. Whatever the legal niceties, the question is: can you stop it? I'm all in favour of stopping it if we can, and it seems to me Anthropic, Google and OpenAI all have every commercial incentive to build in anti-distillation safeguards if they can find some. So it's a self-solving problem, insofar as it has a solution. And I should add — Elon Musk casually admitted a few months ago that his company xAI had distilled from one of the US frontier competitors. So it's not just the Chinese who do this. It's the rough and tumble of the marketplace — not nice, but the practical question is: stop it if we can. Insofar as we can't, we have to live with the reality that Chinese models are good.

    Ed Elson

    Something I can't figure out: if these AI labs are as capable as they say, can they not find some cybersecurity method to stop the distillation happening? If mythos is the most powerful cybersecurity technology the world has ever seen, but we can't figure out how to stop Chinese developers querying and replicating the same software — surely you guys can figure it out. My follow-up: say they do figure it out, say we put an end to Chinese distillation of US AI — wouldn't that both solve America's problems in one fell swoop, and put an end to the progress Chinese AI has been making? Isn't that a kind of poison pill for China?

    Sebastian Mallaby

    I'm not sure. By the way, I think the latest Anthropic models do have some anti-distillation technology built in, so we'll see how effective that turns out to be — it's going to be a cat-and-mouse game, both sides trying to get smarter. But to answer your question: let's posit US labs figure out how to stop distillation. Would the Chinese fall behind a lot, or just a bit? I don't think anybody really knows. I suspect that if they needed to generate their own data, they would — they'd pay more, it would take more time, but they'd get there, because they've got plenty of extremely smart Chinese scientists they could put to work generating training data.

    AI safety and the DeepMind story

    Ed Elson

    We're back with Prof G Markets. Let's turn to the book for a moment. Your most recent book was The Infinity Machine: Demis Hassabis, DeepMind, and the Quest for Superintelligence. One quote from the book stood out: "If you couldn't negotiate safety mechanisms inside one company, what chance would there be to negotiate common safeguards among multiple labs in multiple countries?" That relates to what we're discussing on AI safety and policy — but the important implication is that safety mechanisms couldn't even be negotiated within a single company. What did you learn about the inner workings of these AI labs, and why can't they figure that out?

    Sebastian Mallaby

    Embedded in the story of Google DeepMind and Demis is a kind of morality tale about somebody who really wanted to make AI safe — that was his driving passion from the moment he founded DeepMind in 2010. He bonded with his co-founder Shane Legg at a safety lecture where they discussed the potential for AI to attack humanity by the year 2030, which turns out to be perhaps a prescient projection — at least the capability will be there, whether the AI attacks is a different question.

    Demis Hassabis was thinking about safety from the beginning, and when he sold his company to Google in 2014, a condition of the sale was a safety and ethics oversight board — he said he couldn't let AI be rolled out into the world just on the say-so of the Google corporate board, that there had to be independent people from outside. They talked about Barack Obama as an example — when he was leaving the presidency, could someone of that stature sit on a board saying when it's safe to roll out? That was Demis's vision, coupled with another hope: that all the major scientists would come together in one single effort to roll AI out, so there'd be no competitive pressure to move unsafely and too fast.

    It turns out, and this transpires through the story I tell, that all of Demis's optimistic ideas about making AI safe crashed and burned. The idea of just one lab building AI turned out to be a pipe dream — humanity is too tribal, competitive and disputatious. There will be multiple labs; when you're confronted with the prospect of building a god machine, there'll be plenty of different sects of worshippers trying to do it. And the idea of oversight within Google — ultimately the Google board would not agree to giving outside grandees a veto over how they used a technology they were spending billions of dollars developing. Given their fiduciary obligations, they weren't going to do that. They couldn't.

    So the experiment Demis ran at DeepMind — and I discovered internal documents with the back-and-forth red lines between two teams of lawyers over the exact safety mechanisms they might use, and all the secret strategising Demis did, threatening to spin out of Google if he didn't get the safety oversight he wanted. Then the Google DeepMind general counsel threatened me and said I wasn't allowed to publish any of it, and I said the heck with you, I'm publishing it anyway. It was all quite dramatic, but the bottom line is: it turns out to be impossible to impose safety restraints within one AI lab when that lab is in a competitive posture with respect to others. We saw the same thing play out at OpenAI, more publicly, when the safety board temporarily fired Sam Altman for five days.

    So what this shows is: if you want to stop a race with multiple players, you need government to enforce restraint on all the players at once. And if there are players in China, you need the Chinese government to buy in too, and agree to put restraints on their labs when the US restrains its own. France, Canada — that's fine, the US can compel compliance there, because Cohere in Canada or Mistral in France depend on American technology and the American market to function. With China, you can't compel them. So there need to be two governments doing a deal, where everybody agrees to some caution and checking of models before release. It was the policy of the US government to do none of that — they even issued an executive order banning states from regulating AI in their own way.

    Ed Elson

    But then it seems they've turned on this. Last month Trump signed a new executive order where he basically asks companies to hand over their models to the government, let the government check them, and then greenlight them. On the one hand, that's progress in what you'd think is the right direction; on the other, it's not very harsh or strong — it's basically "hey, could you please send your model over, we'd appreciate that." What do you make of Trump's AI policy at this point, in terms of government oversight of these models and their safety?

    Sebastian Mallaby

    Given my view that government needs to get involved, I've been cheered up by what's happened since April, when mythos first came on the scene and galvanised the US government into paying attention and restricting release. Although you could argue, correctly, that on paper the executive order is a voluntary collaboration system with the frontier labs, the reality is it's not voluntary in the least. Commerce recently called up Altman at OpenAI and ordered him to seek government permission before giving his latest model to any customer — government has to sign off customer by customer. That's extremely heavy-handed. So I think they're in it for real — the government has realised it can't let this disseminate around the world without government control, and we're going to get pretty tough controls.

    I think the gap in the system is that they're not talking about doing this in coordination with China, because the US policy world has two kinds of China expert: the ones who are always hawkish, and the ones who used to be hopeful about collaborating with China but flipped to being uber-hawks once Xi Jinping rose to power and frustrated those hopes. So you've got traditional hawks and new hawks, but both hawkish, and nobody wants to say they want to talk to China. That's the huge gap in the posture. The US government has done a 180 on domestic regulation, and I welcome that. The next thing that has to come, just because it's necessary, is getting over the inhibition about talking to China.

    Ed Elson

    So is the solution to get in a room with Xi Jinping and become partners in tackling this together? It sounds simplistic, but maybe that's actually the way to do it. The alternative would be to force their hand — some policy that says no, you're not getting chips, you're not getting this or that. Your view is that we just need to talk with them and build more of a relationship?

    Sebastian Mallaby

    It's a bit more complicated than that. I think you can talk and put pressure on them at the same time. Going back to the Cold War analogy, there was vicious competition between the Soviet Union and the United States at the same time as collaboration over proliferation. There will be competition — and there are ideas around strengthening chip export controls that I'm not against. Economists sometimes talk about corner solutions: you can have a fully pegged currency or a fully floating one, but if you go for some mushy semi-pegged middle ground, hedge-fund speculators will see you're not really determined to defend it, and they'll eat you for breakfast, lunch and dinner. It's the same with AI policy — there are corner solutions. You could give up the export controls, or offer to loosen them as a show of sincerity, in return for collaboration on fixing the non-proliferation risk. That's one corner solution. Or you don't say that — to the contrary, you tighten up the chip export controls. There's a massive loophole right now: a Chinese model builder can train on the most advanced Nvidia chips all day long, because the cloud compute they access is in Malaysia or some other offshore place that's fully allowed to import those chips. It's nuts that loophole exists — you tell the Chinese they can't use Nvidia chips, then let them use a data centre just across the border. So the other corner solution is to get serious, cut off the loophole, cut off the distillation, and put China in a position so weak it's begging for collaboration. I'm agnostic — I think we need to collaborate, and I'm flexible on how we get there.

    Ed Elson

    Going back to Trump's changing positioning — it used to be we're not going to regulate, we're not having any oversight, because it stifles innovation and we want markets and AI labs to run free. Then mythos happens, Anthropic's model, and it's a real cybersecurity concern. Trump changes his tune and issues an executive order that's actually fairly stringent — they're taking it seriously. Why do you think that happened? What was it about mythos? Was it something to do with China? Why did this ultimately amount to a 180 on AI policy?

    Sebastian Mallaby

    Simply because mythos was so powerful, it was very threatening. The prospect that you could take this model, find code vulnerabilities in every single entity on the internet, and then hack them — that's curtains for the financial system. That's why they took it seriously.

    Ed Elson

    Yeah, fair enough. I think throughout this topic, the logic of the technology is going to force governments to do things which six months earlier they said they'd never do — and that's happened with domestic regulation already in the US. I believe it's going to happen with international collaboration too. I've already started to see pushback — Silicon Valley spent a long time not being friends with Washington, and then in the last couple of years became very close friends with people there. I'd assume this causes a rift again, because a lot of technologists said what they wanted was zero government involvement in AI, and Trump said "sounds good, I'm with you" — and now he's not. I'm not sure what that means for the Silicon Valley–Washington relationship. Do you have any insight? I'd assume it's not going to be great.

    Sebastian Mallaby

    Well, you've got this sort of Putin-and-the-oligarchs story — endless examples of authoritarian governments and big business titans, and where does the power really lie, how stable is that relationship? The answer is it tends not to be stable, point one. And point two: the government wins, because it has the monopoly on coercion. I think Silicon Valley is figuring that out, realising the government is too powerful to ignore. Dario Amodei tried to tell the government it shouldn't use these tools for certain things, like mass domestic surveillance, and the government said get lost — we'll call you a supply-chain risk, we're not going to be dictated to. Who won that fight? Clearly the government did.

    Ed Elson

    It's been fascinating watching Trump use the full power of that coercion even this week, when he stepped into the proceedings of the World Cup and got exactly what he wanted, and the US—

    Sebastian Mallaby

    Absolutely.

    Ed Elson

    —got their player back.

    What Mallaby learned about the people in AI

    Ed Elson

    Just as we start to wrap up — you've studied a lot of the characters in AI. You wrote your book about Demis Hassabis, founder of Google DeepMind, in a sense the OpenAI before OpenAI. From your research, from writing that book, what did you learn about the people in AI? And what has that told you about what might happen next, and who might ultimately win the AI race?

    Sebastian Mallaby

    You've got Sam Altman, who is essentially a commercial opportunist — he wants to win commercially, or at least survive commercially. His drive is to be a big shot; he thought about running for governor of California at one point, being a political big shot, but decided building AI was a bigger big shot, and he wants to put his imprint on it. He's not a PhD scientist — he doesn't even have a first degree, having dropped out of Stanford. That's not to say he isn't massively smart, but he isn't a deep scientist.

    Then you've got people like Dario Amodei and Demis Hassabis, PhD scientists who come at this wanting to use AI to advance deep science. That's their deepest motivation, and I believe it's very deep with both of them — I believe that's the reason they're number one and number two in this race. It's good for recruiting the best scientists, and good for holding together and leading a fundamentally scientific enterprise like building artificial general intelligence.

    The point where this really came home to me was when I was talking to Demis one day about his motivation for building AI, and he said: "Listen, when I'm reading scientific papers at two in the morning, Sebastian, I see reality staring me in the face, calling to me, saying, 'I'm here to be discovered.' And if I had artificial general intelligence, I could discover the fundamental rules that explain the fabric of reality. It would be like understanding all of nature, which presumably may have been created by some kind of divine intelligence. So in this sense, my quest for AGI is kind of like my way of getting closer to what I might call God."

    Ed Elson

    Sebastian Mallaby is the Paul A. Volcker Senior Fellow for International Economics at the Council on Foreign Relations, and a two-time Pulitzer Prize finalist. He's the author of six books, including More Money Than God and The Power Law, which have become investment classics. His latest book is The Infinity Machine: Demis Hassabis, DeepMind, and the Quest for Superintelligence. He also co-hosts a weekly CFR podcast, The Spillover, which examines the ripple effects of global events across policy, geopolitics, economics, technology and financial markets. Sebastian, thank you so much for your time.

    Sebastian Mallaby

    Thank you so much. Nice to talk to you.